<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Privacy_Req_2_Supplemental_Guidance</id>
	<title>Privacy Req 2 Supplemental Guidance - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.idesg.org/index.php?action=history&amp;feed=atom&amp;title=Privacy_Req_2_Supplemental_Guidance"/>
	<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Privacy_Req_2_Supplemental_Guidance&amp;action=history"/>
	<updated>2026-04-16T11:30:28Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.38.4</generator>
	<entry>
		<id>https://wiki.idesg.org/index.php?title=Privacy_Req_2_Supplemental_Guidance&amp;diff=5811&amp;oldid=prev</id>
		<title>Omaerz: 2 revisions imported: Initial Upload of old pages from IDESG Wiki</title>
		<link rel="alternate" type="text/html" href="https://wiki.idesg.org/index.php?title=Privacy_Req_2_Supplemental_Guidance&amp;diff=5811&amp;oldid=prev"/>
		<updated>2018-06-28T04:03:00Z</updated>

		<summary type="html">&lt;p&gt;2 revisions imported: Initial Upload of old pages from IDESG Wiki&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&lt;br /&gt;
{{Under Construction}}&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;lt;&amp;lt; Back to [[Privacy_Req_2|Privacy Requirement 2]]&amp;#039;&amp;#039;&lt;br /&gt;
&lt;br /&gt;
These links are provided as additional informative resources relevant to parties conducting self-assessments (and other identity stakeholders) when applying and evaluating IDEF Baseline Requirement PRIVACY-2.&lt;br /&gt;
&lt;br /&gt;
=== Supplemental Information ===&lt;br /&gt;
&lt;br /&gt;
Contracts, assurances or persistent records of consent or legal authority MUST be established by entities collecting, using, transmitting or storing personal information, so that the information, when passed between entities, is still used in the same manner as originally specified and permitted.  Entities also must assure that their data controls reliably apply these limitations to their future actions.&lt;br /&gt;
&lt;br /&gt;
Please note the applicability of requirement [[Interop_Req_7|INTEROP-7]] regarding limitations imposed by laws.  Please note the applicability of requirements [[Interop_Req_6|INTEROP-6]] and [[Interop_Req_8|INTEROP-8]] regarding limitations arising from the involvement of THIRD-PARTIES such as intermediaries, similar service providers, or FEDERATIONS.&lt;br /&gt;
&lt;br /&gt;
=== References and Guidance (non-normative) ===&lt;br /&gt;
&lt;br /&gt;
* See ISO/IEC 29100 (2011) Privacy Framework, Section 5.3 (&amp;quot;Use, Retention and Disclosure Limitation&amp;quot;) and Section 5.6 (&amp;quot;Purpose Legitimacy and Specification&amp;quot;).  &lt;br /&gt;
* See the &amp;quot;minimum necessary&amp;quot; disclosure standard in HIPAA regulations for health care transactions, 45 CFR Part 164, at §§ 164.502(b) and 164.514(d):  http://www.ecfr.gov/cgi-bin/text-idx?node=pt45.1.164&amp;amp;rgn=div5    &lt;br /&gt;
* See also the Fair Information Privacy Principles:  &amp;quot;Organizations should use PII solely for the purpose(s) specified in the notice. Sharing PII should be for a purpose compatible with the purpose for which the PII was collected.&amp;quot;  http://www.nist.gov/nstic/NSTIC-FIPPs.pdf&lt;br /&gt;
* See OASIS Privacy Management Reference Model (PMRM) v1.0: Section 4.2 (&amp;quot;Service Details&amp;quot;). &lt;br /&gt;
* See Privacy &amp;amp; Biometrics: Building a Conceptual Foundation: Data [p46],Audit [p47], and Storage [p47].&lt;/div&gt;</summary>
		<author><name>Omaerz</name></author>
	</entry>
</feed>